CVE-2007-4559

CRITICAL

Python - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

Exploits (6)

nomisec SCANNER 82 stars
by advanced-threat-research · poc
https://github.com/advanced-threat-research/Creosote
nomisec WORKING POC 1 stars
by depers-rus · poc
https://github.com/depers-rus/CVE-2007-4559
nomisec WORKING POC
by luigigubello · poc
https://github.com/luigigubello/trellix-tarslip-patch-bypass
nomisec WORKING POC
by Ooscaar · poc
https://github.com/Ooscaar/MALW
nomisec WRITEUP
by davidholiday · poc
https://github.com/davidholiday/CVE-2007-4559
nomisec WORKING POC
by m0d0ri205 · poc
https://github.com/m0d0ri205/wargame-tarpioka

Scores

CVSS v3 9.8
EPSS 0.9058
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-22
Status draft

Affected Products (1)

python/python < 3.6.16

Timeline

Published Aug 28, 2007
Tracked Since Feb 18, 2026